CVE-2013-7098: Infradead Openconnect

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.

Affected products

  • Infradead Openconnect: before 5.02 (fixed in 5.02)

Published 2020-02-13. Last modified 2026-06-17.